28 Sun Solaris unused accounts disclosure Finger 2003/11/14 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.3 Corrected the plugin structure and added the accuracy values in 1.3 tcp 79 open|send a b c d e f g h\n|sleep|close|pattern_exists nobody 99 This plugin was written with the ATK Attack Editor. Sun Solaris Other unix systems Configuration A bug in the Sun Solaris finger daemon lets an attacker display all unused accounts. He has to send the request finger 'a b c d e f g h'@target. The finger service, if not needed, should be disabled (in /etc/inetd.conf) or if possible firewalled. Sun Microsystems Inc. published a patch that solve this issue. 20 minutes Yes http://www.securityfocus.com/bid/3457/exploit/ Yes Yes Medium 7 7 6 6 Medium Nessus is able to do the same check. 3457 10788 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch